Patch Tuesday Archive
Patch Tuesday May 2022
Total CVEs
79
Critical
7
Important
68
Exploited
2
Publicly Disclosed
3
All CVEs this month 79
| CVE | Title | Severity | CVSS | Product | Exploited | Disclosed | Diffed |
|---|---|---|---|---|---|---|---|
| CVE-2022-21972 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Point-to-Point Tunneling Protocol | - | - | - |
| CVE-2022-23270 | Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability | Critical | 8.1 |
Windows Point-to-Point Tunneling Protocol | - | - | - |
| CVE-2022-24466 | Windows Hyper-V Security Feature Bypass Vulnerability | Important | 4.1 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-22713 | Windows Hyper-V Denial of Service Vulnerability | Important | 5.6 |
Role: Windows Hyper-V | - | Yes | - |
| CVE-2022-26913 | Windows Authentication Information Disclosure Vulnerability | Important | 7.4 |
Windows Authentication Methods | - | - | - |
| CVE-2022-23267 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2022-26925 | Windows LSA Spoofing Vulnerability | Important | 5.9 |
Microsoft Local Security Authority Server (lsasrv) | Yes | Yes | - |
| CVE-2022-26926 | Windows Address Book Remote Code Execution Vulnerability | Important | 7.8 |
Windows Address Book | - | - | - |
| CVE-2022-26927 | Windows Graphics Component Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-26930 | Windows Remote Access Connection Manager Information Disclosure Vulnerability | Important | 5.5 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2022-26931 | Windows Kerberos Elevation of Privilege Vulnerability | Critical | 7.5 |
Windows Kerberos | - | - | - |
| CVE-2022-26932 | Storage Spaces Direct Elevation of Privilege Vulnerability | Important | 8.2 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2022-26933 | Windows NTFS Information Disclosure Vulnerability | Important | 5.5 |
Windows NTFS | - | - | - |
| CVE-2022-26934 | Windows Graphics Component Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-26935 | Windows WLAN AutoConfig Service Information Disclosure Vulnerability | Important | 6.5 |
Windows WLAN Auto Config Service | - | - | - |
| CVE-2022-26936 | Windows Server Service Information Disclosure Vulnerability | Important | 6.5 |
Windows Server Service | - | - | - |
| CVE-2022-26937 | Windows Network File System Remote Code Execution Vulnerability | Critical | 9.8 |
Windows Network File System | - | - | - |
| CVE-2022-26938 | Storage Spaces Direct Elevation of Privilege Vulnerability | Important | 7 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2022-26939 | Storage Spaces Direct Elevation of Privilege Vulnerability | Important | 7 |
Windows Storage Spaces Controller | - | - | - |
| CVE-2022-26940 | Remote Desktop Protocol Client Information Disclosure Vulnerability | Important | 6.5 |
Remote Desktop Client | - | - | - |
| CVE-2022-22011 | Windows Graphics Component Information Disclosure Vulnerability | Important | 5.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-22012 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 9.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-22013 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-22014 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-22015 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | Important | 6.5 |
Windows Remote Desktop | - | - | - |
| CVE-2022-22016 | Windows PlayToManager Elevation of Privilege Vulnerability | Important | 7 |
Windows Media | - | - | - |
| CVE-2022-22017 | Remote Desktop Client Remote Code Execution Vulnerability | Critical | 8.8 |
Remote Desktop Client | - | - | - |
| CVE-2022-29102 | Windows Failover Cluster Information Disclosure Vulnerability | Important | 5.5 |
Windows Failover Cluster Automation Server | - | - | - |
| CVE-2022-29103 | Windows Remote Access Connection Manager Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Remote Access Connection Manager | - | - | - |
| CVE-2022-29104 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-29105 | Microsoft Windows Media Foundation Remote Code Execution Vulnerability | Important | 7.8 |
Windows Media | - | - | - |
| CVE-2022-29106 | Windows Hyper-V Shared Virtual Disk Elevation of Privilege Vulnerability | Important | 7 |
Role: Windows Hyper-V | - | - | - |
| CVE-2022-29107 | Microsoft Office Security Feature Bypass Vulnerability | Important | 5.5 |
Microsoft Office | - | - | - |
| CVE-2022-29108 | Microsoft SharePoint Server Remote Code Execution Vulnerability | Important | 8.8 |
Microsoft Office SharePoint | - | - | - |
| CVE-2022-29109 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2022-29110 | Microsoft Excel Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Office Excel | - | - | - |
| CVE-2022-29112 | Windows Graphics Component Information Disclosure Vulnerability | Important | 6.5 |
Microsoft Graphics Component | - | - | - |
| CVE-2022-29113 | Windows Digital Media Receiver Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Media | - | - | - |
| CVE-2022-29114 | Windows Print Spooler Information Disclosure Vulnerability | Important | 5.5 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-29115 | Windows Fax Service Remote Code Execution Vulnerability | Important | 7.8 |
Role: Windows Fax Service | - | - | - |
| CVE-2022-29117 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2022-29125 | Windows Push Notifications Apps Elevation of Privilege Vulnerability | Important | 7 |
Windows Push Notifications | - | - | - |
| CVE-2022-29126 | Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability | Important | 7 |
Tablet Windows User Interface | - | - | - |
| CVE-2022-29127 | BitLocker Security Feature Bypass Vulnerability | Important | 4.2 |
Windows BitLocker | - | - | - |
| CVE-2022-29128 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-29129 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-29130 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 9.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-29131 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-29132 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-29133 | Windows Kernel Elevation of Privilege Vulnerability | Important | 8.8 |
Windows Kernel | - | - | - |
| CVE-2022-29134 | Windows Clustered Shared Volume Information Disclosure Vulnerability | Important | 6.5 |
Windows Cluster Shared Volume (CSV) | - | - | - |
| CVE-2022-29135 | Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | Important | 7 |
Windows Cluster Shared Volume (CSV) | - | - | - |
| CVE-2022-29137 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-29138 | Windows Clustered Shared Volume Elevation of Privilege Vulnerability | Important | 7 |
Windows Cluster Shared Volume (CSV) | - | - | - |
| CVE-2022-29139 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-29140 | Windows Print Spooler Information Disclosure Vulnerability | Important | 5.5 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-29141 | Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | Important | 8.8 |
Windows LDAP - Lightweight Directory Access Protocol | - | - | - |
| CVE-2022-29142 | Windows Kernel Elevation of Privilege Vulnerability | Important | 7 |
Windows Kernel | - | - | - |
| CVE-2022-29145 | .NET and Visual Studio Denial of Service Vulnerability | Important | 7.5 |
.NET and Visual Studio | - | - | - |
| CVE-2022-29148 | Visual Studio Remote Code Execution Vulnerability | Important | 7.8 |
Visual Studio | - | - | - |
| CVE-2022-29150 | Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | Important | 7 |
Windows Cluster Shared Volume (CSV) | - | - | - |
| CVE-2022-29151 | Windows Cluster Shared Volume (CSV) Elevation of Privilege Vulnerability | Important | 7 |
Windows Cluster Shared Volume (CSV) | - | - | - |
| CVE-2022-22019 | Remote Procedure Call Runtime Remote Code Execution Vulnerability | Important | 8.8 |
Windows Remote Procedure Call Runtime | - | - | - |
| CVE-2022-30130 | .NET Framework Denial of Service Vulnerability | Low | 3.3 |
.NET Framework | - | - | - |
| CVE-2022-30128 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-30127 | Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | Moderate | 8.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-26905 | Microsoft Edge (Chromium-based) Spoofing Vulnerability | Low | 4.3 |
Microsoft Edge (Chromium-based) | - | - | - |
| CVE-2022-23279 | Windows ALPC Elevation of Privilege Vulnerability | Important | 7 |
Windows ALPC | - | - | - |
| CVE-2022-26923 | Active Directory Domain Services Elevation of Privilege Vulnerability | Critical | 8.8 |
Windows Active Directory | - | - | - |
| CVE-2022-21978 | Microsoft Exchange Server Elevation of Privilege Vulnerability | Important | 8.2 |
Microsoft Exchange Server | - | - | - |
| CVE-2022-29116 | Windows Kernel Information Disclosure Vulnerability | Important | 4.7 |
Windows Kernel | - | - | - |
| CVE-2022-29120 | Windows Clustered Shared Volume Information Disclosure Vulnerability | Important | 6.5 |
Windows Cluster Shared Volume (CSV) | - | - | - |
| CVE-2022-29121 | Windows WLAN AutoConfig Service Denial of Service Vulnerability | Important | 6.5 |
Windows WLAN Auto Config Service | - | - | - |
| CVE-2022-29122 | Windows Clustered Shared Volume Information Disclosure Vulnerability | Important | 6.5 |
Windows Cluster Shared Volume (CSV) | - | - | - |
| CVE-2022-29123 | Windows Clustered Shared Volume Information Disclosure Vulnerability | Important | 6.5 |
Windows Cluster Shared Volume (CSV) | - | - | - |
| CVE-2022-30129 | Visual Studio Code Remote Code Execution Vulnerability | Important | 8.8 |
Visual Studio Code | - | - | - |
| ADV220001 | Upcoming improvements to Azure Data Factory and Azure Synapse Pipeline infrastructure in response to CVE-2022-29972 | Critical | - | Azure SHIR | - | - | - |
| CVE-2022-30138 | Windows Print Spooler Elevation of Privilege Vulnerability | Important | 7.8 |
Windows Print Spooler Components | - | - | - |
| CVE-2022-30190 | Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability | Important | 7.8 |
Microsoft Windows Support Diagnostic Tool (MSDT) | Yes | Yes | - |
Threat Categories 6
| Threat Category | CVEs | Critical |
|---|---|---|
| Remote Code Execution | 26 | 5 |
| Elevation of Privilege | 24 | 2 |
| Information Disclosure | 17 | - |
| Denial of Service | 6 | - |
| Security Feature Bypass | 4 | - |
| Spoofing | 2 | - |
Affected Products 39
| Product | CVEs | Exploited |
|---|---|---|
| Windows LDAP - Lightweight Directory Access Protocol | 10 | - |
| Windows Cluster Shared Volume (CSV) | 8 | - |
| Windows Print Spooler Components | 5 | - |
| Microsoft Graphics Component | 4 | - |
| .NET and Visual Studio | 3 | - |
| Microsoft Edge (Chromium-based) | 3 | - |
| Role: Windows Hyper-V | 3 | - |
| Windows Kernel | 3 | - |
| Windows Media | 3 | - |
| Windows Storage Spaces Controller | 3 | - |
| Microsoft Office Excel | 2 | - |
| Remote Desktop Client | 2 | - |
| Windows Point-to-Point Tunneling Protocol | 2 | - |
| Windows Remote Access Connection Manager | 2 | - |
| Windows WLAN Auto Config Service | 2 | - |
| .NET Framework | 1 | - |
| Azure SHIR | 1 | - |
| Microsoft Exchange Server | 1 | - |
| Microsoft Local Security Authority Server (lsasrv) | 1 | 1 |
| Microsoft Office | 1 | - |
| Microsoft Office SharePoint | 1 | - |
| Microsoft Windows Support Diagnostic Tool (MSDT) | 1 | 1 |
| Role: Windows Fax Service | 1 | - |
| Tablet Windows User Interface | 1 | - |
| Visual Studio | 1 | - |
| Visual Studio Code | 1 | - |
| Windows ALPC | 1 | - |
| Windows Active Directory | 1 | - |
| Windows Address Book | 1 | - |
| Windows Authentication Methods | 1 | - |
| Windows BitLocker | 1 | - |
| Windows Failover Cluster Automation Server | 1 | - |
| Windows Kerberos | 1 | - |
| Windows NTFS | 1 | - |
| Windows Network File System | 1 | - |
| Windows Push Notifications | 1 | - |
| Windows Remote Desktop | 1 | - |
| Windows Remote Procedure Call Runtime | 1 | - |
| Windows Server Service | 1 | - |